Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,341 - 4,360 of 35,345 CVEs
CVE-2026-48017 HIGH - 8.8

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no...

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47684 HIGH - 7.7

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed o...

Vendor: npm
Product: @sync-in/server
Published: Jun 05, 2026
Source: GitHub

Source controller: Improper path handling allows traversal

Vendor: go
Product: github.com/fluxcd/source-controller
Published: Jun 05, 2026
Source: GitHub

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47419 HIGH - 8.3

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 05, 2026
Source: GitHub

DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

Vendor: npm
Product: dbgate
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47668 CRITICAL - 10.0

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

Vendor: npm
Product: dbgate-serve
Published: Jun 05, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment path could read any file in shared storage, including attachments belonging to other bases and workspaces, because the MCP readAttachment tool did not verif...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (packages/nc-gui/composables/useSharedFormViewStore.ts) in NocoDB writes the form's redirect_url to window.location.href after a same-host check that does not validate the URL sche...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, two concurrent token-exchange requests using the same OAuth authorization code could each mint a distinct valid (access_token, refresh_token) pair, breaking the single-use guarantee that PKCE relies on. This vulnerability...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create permission can attach a SQLite source pointing at an arbitrary file on the NocoDB host, including NocoDB's own internal databases. The SQLite client and the base/integration cre...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create permission can inject SQL into the bulk groupBy endpoint by setting a column's title to a SQL fragment. The bulk groupBy path in group-by.ts builds three database-specific kne...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HTML in row comments that executed as script when other users hovered over the comment in the expanded form view. The comment write paths persisted the raw comment body with no serve...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw TCP socket to the user-supplied database host without resolving and range-checking the destination, so private and link-local addresses (including IPv4-mapped IPv6 forms and local...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub
CVE-2026-9270 CRITICAL - 9.1

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change...

Vendor: binary
Product: datadog\
Published: Jun 05, 2026
Source: NVD

7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image handler's File Identifier Descriptor parser. In CFileId::Parse (CPP/7zip/Archive/Udf/UdfIn.cpp), after validating size < 38 + idLen + i...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-48101 MEDIUM - 6.5

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB) without ze...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-11362 CRITICAL - 9.8

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, w...

Vendor: BINARY
Product: DataDog::DogStatsd
Published: Jun 05, 2026
Source: NVD
CVE-2026-11336 MEDIUM - 6.3

A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of the file dashboard_page/admin_page.php of the component Admin Interface. The manipulation of the argument User...

Vendor: tittuvarghese
Product: CollegeManagementSystem
Published: Jun 05, 2026
Source: NVD

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise another workspace's integration through the testConnection endpoint by supplying its ID, because the integration was fetched in a bypass scope and the caller's permission c...

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub